CVE-2024-21586: Junos OS: SRX Series and NFX Series: Specific valid traffic leads to a PFE crash
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series and NFX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
If an affected device receives specific valid traffic destined to the device, it will cause the PFE to crash and restart. Continued receipt and processing of this traffic will create a sustained DoS condition.
This issue affects Junos OS on SRX Series:
21.4 versions before 21.4R3-S7.9, 22.1 versions before 22.1R3-S5.3, 22.2 versions before 22.2R3-S4.11, 22.3 versions before 22.3R3, 22.4 versions before 22.4R3.
This issue affects Junos OS on NFX Series:
21.4 versions before 21.4R3-S8, 22.1 versions after 22.1R1, 22.2 versions before 22.2R3-S5, 22.3 versions before 22.3R3, 22.4 versions before 22.4R3.
Junos OS versions prior to 21.4R1 are not affected by this issue.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21586?
CVE-2024-21586 is categorized as a high severity vulnerability due to its potential to cause a Denial-of-Service (DoS) on affected devices.
How do I fix CVE-2024-21586?
To fix CVE-2024-21586, it is recommended to upgrade the Junos OS to a version that is not vulnerable, specifically to 21.4R3-S8 or later for affected versions.
Which devices are affected by CVE-2024-21586?
CVE-2024-21586 affects Juniper Networks Junos OS on SRX Series and NFX Series devices running specified vulnerable versions.
Can CVE-2024-21586 be exploited remotely?
Yes, CVE-2024-21586 can be exploited by an unauthenticated, network-based attacker.
What type of attack does CVE-2024-21586 enable?
CVE-2024-21586 enables an attacker to execute a Denial-of-Service (DoS) attack on affected devices.